Your MDR Provider May Detect Threats but Doesn't Stop Them.

July 29, 2026

Your MDR provider might not be allowed to stop an attack, even if they spot it right away. Most buyers never find that out until an incident forces the question.

Detection and Response Are Not the Same Service

Here's the question that actually matters: when something goes wrong, can your provider act on it themselves, or do they just tell you and wait for your team to respond? Most contracts use the word "response" for both. They are not the same service. One protects you. The other just keeps you informed while the clock runs.

What I Found Inside One Provider's Contract

I sat through an evaluation of a well known provider recently, for our own portfolio. On paper, full Manage Detection and Response. In practice, the service watched a client's environment, and when something looked wrong, it sent an email. That was it. No ability to reach into the client's own tools. They could see a problem. They could not touch it.

That's the mechanism hiding inside a lot of MDR contracts. A provider can watch closely, alert you accurately, and still leave the entire response sitting in your hands, because watching and acting are two different services sold under one name.

Why Some Providers Work This Way on Purpose

There's a legitimate reason for this. Plenty of organizations don't want an outside company automatically isolating a server or disabling an account without asking first. That's a fair boundary to set. The mistake isn't setting it. The mistake is not knowing you set it.

Questions to Ask Before You Sign or Renew

Skip the brochure and test the actual mechanism. Ask your provider to walk you through exactly what happens when an alert fires, step by step. Ask if they can isolate a machine, kill a bad process, disable an account, cut off network access, or lock down a device themselves, without waiting on your team. Ask which of those happen automatically and which need your approval first. Ask what happens in the first minute of a real event, before anyone is even on the phone.

If you can't answer that last one right now, you don't actually know what you bought.

Why Speed Makes This Worse Than It Used to Be

A few years ago, attackers needed over an hour to move across a network once they got in. An email followed by someone investigating still had a real shot at working. CrowdStrike tracks this every year. The average has dropped from about 98 minutes in 2021 to 29 minutes in their latest report. The fastest breakout they recorded was 27 seconds. At that speed, a watch and notify model gives your team almost no window to step in.

What Happened at Target

Six months before the biggest retail breach in American history, Target's detection system worked exactly as it should have. It caught the attackers loading malware. It fired alerts five separate times. A security team watching around the clock flagged every one to headquarters.

Then nothing happened. Flagging an alert isn't the same as acting on it, and the handoff to someone who could actually respond broke down. The malware ran for two more weeks. Forty million cards walked out the door.

The tool never failed. Everything after the alert did.

What the Insurance Data Shows

The clearest proof of what this costs comes from the people with no reason to get it wrong: the insurers paying the claims. A study of real cyber insurance ransomware claims split victims by what security they actually had running.

Companies with self managed detection tools, capable tools run by their own team, took a median of 55 days to recover, with a median claim near $500,000. Companies with real MDR behind the same kind of tool recovered in a median of three days, with a median claim near $75,000.

The gap wasn't the tool. It was whether anyone could act on what the tool found. The self managed group even recovered slower than companies running only basic protection with no advanced tooling at all.

Before You Renew

Whatever process you use to evaluate a provider, make sure someone checks what the contract actually authorizes after an alert, not just what the platform can technically do. Marketing tells you what the tool can do. The contract tells you what the provider is allowed to do. That's the part most buyers never check, and it's almost always sitting in the fine print, not the pitch.

We see this gap constantly across the 967 providers we track and evaluate for clients in this market.

If you're evaluating an MDR provider right now, or renewing one you haven't pressure tested in a while, this is where to start.

We'll show you what real world fit looks like across 967 providers. Get Started.
No pitch. No prep. Just answers.